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In the claims: 

1. (currently amended) A method for establishing a secure transmission channel from 
softwar e a process of a first node to softwar e a process of a second node comprising; 

sending a key, identification of the first node, and identification of the second node from a 
gecurehardware of the first node to a secure hardware of the second node , such that the key is 
inaccessible by all processes running on the first node and unauthorized processes running on the 
first node are unable to send unauthorized messages through the secure hardware of the first 
node : 

receiving the key, identification of the first node, and identification of the second node by 
the secure hardware of the second node; 

verifying the identification of the first node and the identification of the second node fa^ 
the secure h ardware of the second node; and, 

storing the key at the secure hardware of the second node , such that the key is inaccessible 
by all processes running on the second node r 

wherein the secure hardware of the first hardware and the secure hardware of the second 

node establish a channel over which the process of the first node and the process of the second 
node are able to communicate . 

2. (cancelled) 

3. (original) The method of claim 1, wherein each of the first node and the second node 
comprises one or more partitions, each partition corresponding to an operating system instance. 

4. (currently amended) The method of claim 3, wherein the softwar e process of the first 
node comprises a process running in one of the one or more partitions of the first node. 
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5. (currently amended) The method of claim 4, wherein the identification of the first node 
comprises at least one of identification of the process running in the one of the one or more 
partitions of the first node, and identification of the one of the one or more partitions of the first 
node. 

6. (currently amended) The method of claim 3, wherein the identification of the second node 
comprises at least one of identification of [[a]] the p rocess running in one of the one or more 
partitions of the second node, and identification of the one of the one or more partitions of the 
second node. 

7. (currently amended) The method of claim 1, wherein each of the securehardware of the 
first node and the hardware of the second node comprises a connection management mechanism. 

8. (currently amended) The method of claim 1, wherein verifying the identification of the 
first node and the identification of the second node at by the secure hardware of the second node 
comprises verifying the identification of the first node and the identification of the second node in 
a channel state table accessible by the secure h ardware of the second node and inaccessible by all 
the softwar e processes of the second node. 

9. (cancelled) 

10. (currently amended) The method of claim 1, further comprising: 
creating a message at the s oftware process of the second node; 
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sending the message, the key, the identification of the first node, and the identification of 
the second node from the secure hardware of the second node to the secure hardware of the first 
node; 

receiving the message, the key, the identification of the first node, and the identification of 
the second node by the secure hardware of the first node; 

verifying the key at the secure hardware of the first node; and, 

processing the message at the softwar e process of the first nod e, where the key has been 
successfully verified at the secure hardware of the first node . 

1 1 . (currently amended) A computerized system comprising: 

a first secure connection management hardware mechanism at a first node to maintain first 
keys for secure communication to first processes running in one or more £&st partitions of the first 
node from second processes running in one or more seeend-partitions of a second node, the first 
keys inaccessible by th e first all processes running on the partitions of the first node and running 
on the partitions of the second node r each first key used for secure communication to one of the 
first processes from one of the second processes, and unauthorized processes g unnin g on the first 
node are unable to send unauthorized messages through the first secure connection management 
hardware of the first node : and, 

a second secure connection management hardware mechanism at the second node to 
maintain second keys for secure communication to the second processes from the first processes, 
the second keys inaccessible by th e se cond all processes running on the partitions of the first node 
and running on the partitions of the second node , each second key used for secure communication 
to one of the second processes from one of the first processes* 

wherein the first and the second secure connection management hardware mechanisms 

establish a channel over which the first processes and the second processes are able to 
communicate . 
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1 2. (currently amended) The system of claim 1 1 , further comprising: 

a first key table at the first node to store the first keys, the first key table accessible by the 
first secure connection management hardware m echanism but inaccessible by the first processes; 
and, 

a second key table at the second node to store the second keys, the second key table 
accessible by the second secure connection management hardware mechanism but inaccessible by 
the second processes. 

13. (currently amended) The system of claim 1 1, further comprising: 

a first connection table at the first node and accessible by the first secure connection 
management hardware mechanism and the first processes, the first connection table having a 
number of first entries, each first entry identifying one of the first processes, one of the second 
processes with which the one of the first processes is securely communicating, and one of the one 
or more «eeeiid-partitions of the second node in which the one of the second processes is running; 
and, 

a second connection table at the second node and accessible by the second secure 
connection management hardware m echanism and the second processes, the second connection 
table having a number of second entries, each second entry identifying one of the second 
processes, one of the first processes with which the one of the second processes is securely 
communicating, and one of the one or more fifs^-partitions of the first node in which the one of 
the first processes is running. 

14. (currently amended) The system of claim 13, further comprising: 

a first key table at the first node having a number of first key entries, each first key entry 
corresponding to a first entry of the first connection table and storing one of the first keys, the 
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first key table accessible by the first secure connection management hardware mechanism but 
inaccessible by the first processes; and, 

a second key table at the second node having a number of second key entries, each second 
key entry corresponding to a second entry of the second connection table and storing one of the 
second keys, the second key table accessible by the second secure connection management 
hardware mechanism but inaccessible by the second processes. 

15. (curently amended) An article comprising: 

a computer-readable signal - bearing recordable data storage medium; and, 
means in the medium for maintaining keys for secure communication to first processes 
running in one or more fifst-partitions of a first node from second processes running in one or 
more seeoad-partitions of a second node, the keys inaccessible by th e fir s t all processes, each key 
used for secure communication to one of the first processes from one of the second processes* 
wherein unauthorized processes are unable to send unauthorized messages . 

16. (original) The article of claim 15, wherein the means in the medium is further for storing 
the keys in a key table inaccessible by the first processes. 

17. (curently amended) The article of claim 15, wherein a connection table at the first node is 
accessible by the means in the medium and the first processes, the connection table having a 
number of entries, each entry identifying one of the first processes, one of the second processes 
with which the one of the first processes is securely communicating, and one of the one or more 
second partitions of the second node in which the one of the second processes is running. 

18. (original) The article of claim 17, wherein a key table at the first node is accessible by the 
means in the medium but inaccessible by the first processes, the key table having a number of key 
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entries, each key entry corresponding to an entry of the connection table and storing one of the 
keys. 



19.-20. (cancelled) 
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